[security] Self-XSS in setup (host parameter), see PMASA-2011-19